Getting Data In

Event count is showing Zero

Namo
Explorer

I am new to splunk and  observing the event count and current size showing a 0, even though we can search on the index and have data . Any insights will be helpful.

Labels (1)
0 Karma

Namo
Explorer

 hi Giuseppe,
Thanks for the response.
the issue is for both internal and external indexes , the event count  and  current size is not showing any value. You mentioned the default search path, could you please shed some info on that,may be i can explore that option.

Namo_0-1718724000594.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Namo,

what's the search you runned?

did you inserted the name of the index in your main search or at least index=*?

maybe the index you're using isn't in the default search path, so you don't find anything.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...